2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4292 | MEDIUM | 5.3 | 0.4% | Sep 21, 2023 | Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a SQL injection v... |
| CVE-2023-4291 | CRITICAL | 9.8 | 1.0% | Sep 21, 2023 | Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code exe... |
| CVE-2023-4152 | HIGH | 7.5 | 0.7% | Sep 21, 2023 | Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a path traversal ... |
| CVE-2023-43669 | HIGH | 7.5 | 1.6% | Sep 21, 2023 | The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consum... |
| CVE-2023-39252 | MEDIUM | 5.9 | 0.3% | Sep 21, 2023 | Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated a... |
| CVE-2023-43135 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attacke... |
| CVE-2023-39675 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key paramet... |
| CVE-2023-37279 | HIGH | 7.5 | 0.8% | Sep 20, 2023 | Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can s... |
| CVE-2023-36234 | MEDIUM | 5.4 | 0.4% | Sep 20, 2023 | Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in d... |
| CVE-2023-36109 | CRITICAL | 9.8 | 2.0% | Sep 20, 2023 | Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_str... |
| CVE-2023-34575 | CRITICAL | 9.8 | 0.7% | Sep 20, 2023 | SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL comma... |
| CVE-2023-42322 | CRITICAL | 9.8 | 0.7% | Sep 20, 2023 | Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. |
| CVE-2023-42321 | HIGH | 8.8 | 0.4% | Sep 20, 2023 | Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary co... |
| CVE-2023-39677 | HIGH | 7.5 | 30.8% | Sep 20, 2023 | MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInf... |
| CVE-2023-38876 | MEDIUM | 6.1 | 0.7% | Sep 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to ex... |
| CVE-2023-38875 | MEDIUM | 6.1 | 0.8% | Sep 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to ex... |
| CVE-2023-22024 | MEDIUM | 5.5 | 0.2% | Sep 20, 2023 | In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6... |
| CVE-2023-43138 | HIGH | 8.8 | 2.1% | Sep 20, 2023 | TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT ru... |
| CVE-2023-43137 | HIGH | 8.8 | 2.1% | Sep 20, 2023 | TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rul... |
| CVE-2023-43134 | CRITICAL | 9.8 | 0.8% | Sep 20, 2023 | There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive ... |
| CVE-2023-42335 | HIGH | 8.8 | 1.1% | Sep 20, 2023 | Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to exec... |
| CVE-2023-42334 | MEDIUM | 6.5 | 0.6% | Sep 20, 2023 | An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalat... |
| CVE-2023-42331 | HIGH | 8.8 | 1.2% | Sep 20, 2023 | A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.... |
| CVE-2023-42147 | HIGH | 7.5 | 0.4% | Sep 20, 2023 | An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component. |
| CVE-2023-41484 | HIGH | 8.1 | 0.6% | Sep 20, 2023 | An issue in cimg.eu Cimg Library v2.9.3 allows an attacker to obtain sensitive information via a crafted JPEG file. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now